>Interestingly, the vulnerable code had been changed upstream the previous year, but the commit was not documented as a security fix and received no CVE.3 This might be a reason why Debian 12 and 13 have not received the security relevant backports in time.
Ooof, keeping packages like this up to date with the rate of updates and churn is a mess.
"Just run this sudo curl install.sh | bash that further retrieves 165 npm dependencies, I'm sure everything will be fine" ...
If its just tedious, I bet there is room for agentic/automation to keep things tidy.